• DocumentCode
    2484387
  • Title

    Notice of Retraction
    A Static Analysis Tool for Detecting Web Application Injection Vulnerabilities for ASP Program

  • Author

    Xin-hua Zhang ; Zhi-jian Wang

  • Author_Institution
    Comput. & Inf. Eng. Coll., Hohai Univ., Nanjing, China
  • fYear
    2010
  • fDate
    22-23 May 2010
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    Notice of Retraction

    After careful and considered review of the content of this paper by a duly constituted expert committee, this paper has been found to be in violation of IEEE´s Publication Principles.

    We hereby retract the content of this paper. Reasonable effort should be made to remove all past references to this paper.

    The presenting author of this paper has the option to appeal this decision by contacting TPII@ieee.org.

    Publicly reported vulnerability in recent years strong growth of the Web Application , Cross-site scripting (XSS) and SQL injection have been the most dominant class of web vulnerabilities, Web application security has been a great challenge. For the case, the static analysis tools ASPWC presented in this paper to detect XSS attacks and SQL injection vulnerabilities based on taint analysis, It tracks various kinds of external input, tags taint types, constructing control flow graph is constructed based on the use of data flow analysis of the relevant information, taint data propagate to various kinds of vulnerability functions, and detect the XSS or SQL Injection vulnerability in web application´s source code. Experiments show that the detection approach is an effective way; it can be used to detect the XSS and SQL Injection vulnerability in the web application program based on ASP technology development.
  • Keywords
    SQL; authoring languages; data flow analysis; ASP program; SQL injection; Web application injection vulnerabilities; control flow graph; cross site scripting; data flow analysis; static analysis tool; Application software; Application specific processors; Computer security; Databases; Educational institutions; Flow graphs; Information analysis; Information security; Software design; Software testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    e-Business and Information System Security (EBISS), 2010 2nd International Conference on
  • Conference_Location
    Wuhan
  • Print_ISBN
    978-1-4244-5893-6
  • Type

    conf

  • DOI
    10.1109/EBISS.2010.5473561
  • Filename
    5473561